2026 CVE Vulnerabilities

56,195 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-23175HIGH7In the Linux kernel, the following vulnerability has been resolved: net: cpsw: Execute ndo_set_rx_mode callback in a wo...
CVE-2026-23171HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bonding: fix use-after-free due to enslave fail aft...
CVE-2026-23162HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/nvm: Fix double-free on aux add failure Aft...
CVE-2026-23158HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix UAF in configfs release path T...
CVE-2026-23156HIGH7.8In the Linux kernel, the following vulnerability has been resolved: efivarfs: fix error propagation in efivar_entry_get...
CVE-2026-1843HIGH7.2The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versi...
CVE-2026-2024HIGH7.5The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up...
CVE-2026-1988HIGH7.5The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all vers...
CVE-2026-0753HIGH7.2The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' p...
CVE-2026-2469HIGH7.6Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elem...
CVE-2026-2144HIGH8.1The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in...
CVE-2026-0692HIGH7.5The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions...
CVE-2026-1844HIGH7.2The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' param...
CVE-2026-1841HIGH7.2The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2026-26334HIGH7.8Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (V...
CVE-2026-26269HIGH7.5Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim'...
CVE-2026-2441HIGH8.8Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside...
CVE-2026-26264HIGH8.1BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a ma...
CVE-2026-26208HIGH7.8ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserial...
CVE-2026-26187HIGH8.1lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local bl...
CVE-2026-25991HIGH7.7Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, the...
CVE-2026-21878HIGH7.5BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability ...
CVE-2026-23111HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in...
CVE-2026-1619HIGH8.3Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploita...
CVE-2026-1618HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now